Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
minitech
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
91.
▲
by
minitech
10mo ago
That was how psycopg2 did it, but now the package is psycopg (again) version 3, as it should be. Python package management has come a long way since psycopg 1 was created. urllib2/3’s etymology is different: urllib2’s name comes from
92.
▲
by
minitech
10mo ago
It’s not necessary to cater to the absolute least competent end user to begin with, but inserting slowdown bugs does not even achieve that . (Note that the bit about the breaking of dependent libraries you’re quoting is still not actually
93.
▲
by
minitech
10mo ago
A breaking change in a dependency doesn’t cause a full-stop to a service at all. The old version continues to work. Making subtly harmful changes so that new broken versions sneak in is just a bad idea and totally unnecessary.
94.
▲
by
minitech
10mo ago
This is so much worse than just making the breaking change.
95.
▲
by
minitech
10mo ago
It’s more like playing a casual tournament at your local chess club without an engine.
96.
▲
by
minitech
10mo ago
It was pretty boring trying to place against aggressive AI pipelines like yours throughout the explicit requests not to use them[1]. I’m sorry to hear it became boring for you too. [1] https://web.archive.org/web/202412
97.
▲
by
minitech
11mo ago
No, just competing priorities.
98.
▲
by
minitech
11mo ago
The convenience advantage is significant, and it goes farther than convenience, since it’s very common for services to have their verification mail blocked or sent to spam. (Bonus pain: there’s no user-visible difference between delayed and
99.
▲
by
minitech
11mo ago
tabindex=0 does sort naturally into the automatic tabindex order. > So you are jumping through all the other tabindex elements This part is correct (for elements with an explicit positive tabindex), which is why specifying an explicit
100.
▲
by
minitech
11mo ago
The problem is that not enough people care about reviewing dependencies’ code. Adding what they consider noise to the diff doesn’t help much (especially if what you end up diffing is actually build output).
101.
▲
by
minitech
11mo ago
Yeah, people invented the concept of packages and package management because they couldn’t conceive of vendoring (which is weird considering basically all package managers make use of it themselves) and surely not because package management
102.
▲
by
minitech
11mo ago
> is the container on the machine? > is he just saying always run your code in a container? yes > isn't that running things on your machine? in this context where they're explicitly contrasted, it isn't running thing
103.
▲
by
minitech
11mo ago
> Security theatre is all it is. Protect us from petty thieves Even picking the most dismissive wording you can, you contradict yourself.
104.
▲
by
minitech
11mo ago
Yes, that. Could be to a lookalike domain name, for example.
105.
▲
by
minitech
1y ago
> Even if that were the case, sorting a list that's already sorted is basically free. Any reasonable sort method (like the builtin one in a JS runtime) will check for that before doing anything to the list. That’s n−1 pairs of eleme
106.
▲
by
minitech
1y ago
It’s been around since the root commit in 2015: https://github.com/microsoft/vscode/blob/8f35cc4768393b25468...
107.
▲
by
minitech
1y ago
That quote is probably referring to the limitations listed later on the page ( https://cheatsheetseries.owasp.org/cheatsheets/Cross-Site_Re... ). I think if you understood that this was the caveat, you wouldn’t use the p
108.
▲
by
minitech
1y ago
That’s not correct, or is at least seriously misleading. `Sec-Fetch-Site` is a replacement for CSRF tokens. The sole purpose of CSRF tokens is to prevent CSRF, and enforcing that all unsafe[1]-method requests have a `Sec-Fetch-Site: same-
109.
▲
by
minitech
1y ago
Not relevant to the flavoring question, since nobody uses lead as a sweetener now.
110.
▲
by
minitech
1y ago
This is the context: > > The reason to care about compile time is because it affects your iteration speed. You can iterate much faster on a program that takes 1 second to compile vs 1 minute. > Color me skeptical. I've only go
111.
▲
by
minitech
1y ago
The part that seems strange to me is your evidence that multi-minute compile times are acceptable being couple-second compile times. It seems like everyone actually agrees that couple-second iteration is important.
112.
▲
by
minitech
1y ago
None of the things you mentioned are clearly related to each other. “It basically means you can always override anything, which allows for monkey patching and proxying and adapter patterns and circular imports” is not true. “They’re the rea
113.
▲
by
minitech
1y ago
> Further, using Rust as an example, even a project which takes 5 minutes to build cold only takes a second or two on a hot build thanks to caching of already-built artifacts. So optimizing compile times isn’t worthwhile because we alrea
114.
▲
by
minitech
1y ago
If you ignore the other half of the suggestion, yeah. Designating trusted reviewers to audit dependencies like React would be downright cheap at scale. The issue is just setting up and popularizing the systems to achieve this. It’s a little
115.
▲
by
minitech
1y ago
Lockfiles are a more standard and probably better way to do this. (People do need to pay more attention to lockfile diffs.)
116.
▲
by
minitech
1y ago
Query builders that operate at the SQL level. (A popular example of that in Python is SQLAlchemy Core, but there are better ways to do it, especially in better-typed languages.)
117.
▲
by
minitech
1y ago
> Sadly we don't have any defense against 0 days if an emergency patch is indistinguishable from an attack itself. Reading the code content of emergency patches should be part of the job. Of course, with better code trust tools (the
118.
▲
by
minitech
1y ago
You can’t replace existing versions on npm. (But probably more important is what @jffry mentioned – yes, lockfiles include hashes.)
119.
▲
by
minitech
1y ago
> Because ads are not how malware is distributed? Malware is absolutely distributed through ads. In the case of more reputable ad platforms that don’t allow arbitrary scripts, it’s by linking to malware, but they’re also used to serve dr
120.
▲
by
minitech
1y ago
And this cookie isn’t for tracking purposes anyway, so doesn’t require a notice.
More ›